Hackers say McKesson data breach exposed records from tens of millions of patients
Medical device and pharmaceutical supply company McKesson confirmed on Friday that it was hit by a cyberattack that may have exposed patient data to hackers. The incident was first revealed by the alleged perpetrators—the infamous hacker group ShinyHunters, who have claimed credit for the attack.
If their claims are to be believed, the cybersecurity incident compromised 284 million records, impacting tens of millions of patients. CyberInsider was the first to report the news, with ShinyHunters—a prolific cybercrime cell known for its attacks on healthcare and public sector entities—speaking to the outlet directly.
Shortly after the report, McKesson confirmed that the data breach was real, releasing a disclosure statement on its website and vowing to provide victims with identity theft protection services once they’re all identified.
“Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response,” the company wrote. “Our investigation remains ongoing, and we are working to fully ascertain the nature and scope of the incident so that we can provide accurate and concrete information as it becomes available.”
In an update over the weekend, McKesson said stolen data was “associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units.”
Regardless of what business segment the data came from, a sample of the trove revealed by ShinyHunters shows that it contains sensitive personal information, including details on medical diagnoses and treatments.
Phishing for a way inside
According to CyberInsider, the group said it was able to gain access to McKesson’s network by voice-phishing a couple of employees who provided credentials that allowed the group to access data from the company’s cloud storage partners, in this case Salesforce and Snowflake.
From there, ShinyHunters told reporters that it was able to exfiltrate files directly from McKesson, which it said included contact details for patients—full names, home addresses, dates of birth, phone numbers, emails, and Social Security numbers—including healthcare-specific identifiers, such as medical record numbers.
The hackers also claimed to have extensive medical records on patients that include everything from prescription records to autopsy details. In some cases, ShinyHunters claimed to have predictive health data, used to assess cancer risk, on specific patients.
CyberInsider said the data trove may extend beyond patient information: “ShinyHunters says the dataset contains employee records with names, addresses, email addresses, phone numbers, departments and job roles, as well as information about physicians and clinics using McKesson services. Doctor and patient communications have also been exfiltrated, though the threat actors said this concerns only email content, not attachments,” the outlet wrote.
Physicians’ names, contact information, and details on the size and scope of practices may also be discernible from certain records, reporters added.
ShinyHunters added that it has made a ransom demand of McKesson, offering to delete the data in exchange for $55 million.
It is unclear if the hacker group was able to deploy ransomware as part of its attack, as such details were not included in the report from CyberInsider.
So far McKesson, a publicly traded company, has provided few details about the incident. However, it did confirm in a regulatory filing with the U.S. Securities and Exchange Commission that it first discovered the “cybersecurity incident affecting its information systems” on Aug. 25.
The New York-based hospital supply company added that it has yet to assess what impact the data breach will have on its business operations. It has also yet to confirm or deny whether the specific claims made by ShinyHunters are true. HealthExec reached out for more details.
This is a developing story.
